Source: OJ L, 2024/436, 2.2.2024Consolidated text

Current language: EN

Article 5 Cooperation and assistance between the audited provider and the auditing organisation


    1. At a time agreed with the auditing organisation, and in any event prior to the performance of any audit procedure, the audited provider shall transmit to the selected auditing organisation at least the following information:

      1. a description of the internal controls put in place with respect to each audited obligation and commitment, including related indicators and all present and historical measurements, and benchmarks used by the audited provider to assert or monitor compliance with the audited obligations and commitments, as well as any supporting documentation;

      2. its preliminary analysis of inherent and control risks, where the audited provider has performed such an analysis, and any supporting documentation;

      3. information about any relevant decision-making structures, competences of departments of the provider, including the compliance function pursuant to Article 41 of Regulation (EU) 2022/2065, relevant IT systems, data sources, processing and storage, as well as explanations of relevant algorithmic systems and their interactions.

    1. The audited provider shall grant the auditing organisation, without undue delay, access to all data necessary for the performance of the audit, including personal data, documentation, information on procedures and processes, and to the information technology systems, testing environments, personnel and premises of that provider, and any relevant sub-contractors.

    1. The audited provider shall make all necessary resources available and provide the auditing organisation with the assistance and explanations necessary for the auditing organisation to analyse the relevant information and to carry out tests, including where the information requested by the auditing organisation in accordance with Article 37(3) of Regulation (EU) 2022/2065 is held by a third-party contracted by the audited provider.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod